VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-70547Medium· 4.3
1mo ago

An authenticated user without repository read permission may access package metadata under specific conditions.

An authenticated user without repository read permission may access package metadata under specific conditions.

▾ Sunlitjfrog · artifactoryEPSS 0.28%via NVD
CVE-2026-69107Medium· 5.9
1mo ago

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

▾ Sunlitjfrog · artifactoryEPSS 0.41%via NVD
CVE-2026-63300Critical· 9.9
1mo ago

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security res…

▾ Midnightcanonical · lxdEPSS 0.54%via NVD
CVE-2026-73287Medium· 5.4
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Act…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-73265Medium· 6.5
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals wi…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-47233Medium· 6.5
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` h…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-47226Medium· 6.5
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorizati…

▾ SunlitEPSS 0.35%via NVD
GHSA-xx34-6cjg-prh8Critical· 8.6
1mo ago

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-mxjf-vfmv-qfm6Medium· 5.8
1mo ago

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

Duplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-68758Medium· 6.5
1mo ago

A low-privileged authenticated user may access restricted support information under specific conditions.

A low-privileged authenticated user may access restricted support information under specific conditions.

▾ SunlitEPSS 0.35%via NVD
CVE-2026-65938Medium· 4.3
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-65926Low· 3.1
1mo ago

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-68754Medium· 6.5
1mo ago

A repository publisher without delete permission may modify protected package content under specific conditions.

A repository publisher without delete permission may modify protected package content under specific conditions.

▾ SunlitEPSS 0.31%via NVD
CVE-2026-68753Medium· 5.3
1mo ago

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

▾ SunlitEPSS 0.31%via NVD
CVE-2026-66380Medium· 4.3
1mo ago

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-66379Medium· 4.3
1mo ago

An authenticated user may view private Puppet module metadata without repository read access.

An authenticated user may view private Puppet module metadata without repository read access.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-66378Medium· 4.3
1mo ago

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-66377Medium· 5.3
1mo ago

An unauthenticated user may access restricted repository information under specific conditions.

An unauthenticated user may access restricted repository information under specific conditions.

▾ SunlitEPSS 0.36%via NVD
CVE-2026-66375High· 8.1
1mo ago

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-64954High· 8.2
1mo ago

Velociraptor allows scheduling new collections via VQL queries in notebooks

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which reset…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-18652Medium· 6.5
1mo ago

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowi…

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowi…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-72805Medium· 5.8
1mo ago

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disclosure of protected document content and metadata. Anonymous readers or publish RoleRead…

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via NVD
CVE-2026-72797Medium· 5.8
1mo ago

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted notebook identifiers, names, and lock states without publish-access filtering. Anonymous read…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-72789High· 8.6
1mo ago

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypte…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.50%via NVD
CVE-2026-73301Medium· 4.3
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate te…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-69115Medium· 6.5
1mo ago

OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/g…

OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-only management API endpoints by submitting POST requests with a regular user bearer token to /user/get_users, /user/g…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-69113Medium· 5.4
1mo ago

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request b…

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request b…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-73249High· 7.5
1mo ago

calibre is an e-book manager

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.ch…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-48763High· 8.2
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-48495High· 7.1
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptog…

▾ TwilightEPSS 0.35%via NVD
CWE-862 vulnerabilities (CVEs) — page 30 · VulnSea